摘要
网络安全防护是我国铁路信号系统的重中之重。全面分析了当前我国铁路信号系统的网络安全风险;根据现场实际安全需求,结合等级保护制度,采取网络安全域划分、网络逻辑隔离、网络物理隔离、身份鉴别增强、安全运维审计等安全措施,构建集防护、检测、响应、恢复于一体的纵深安全防御体系;选取列车调度指挥系统/调度集中系统为示范性研究对象,分析本安全防护措施的实践应用情况。研究表明:本防护措施可以有效抵御铁路信号系统中现存的安全风险,提高网络安全保障能力,确保铁路信号系统的安全稳定运行。
Network security protection is the top priority of railway signaling system in China.A comprehensive analysis of the current network security risks of railway signaling system is conducted.According to the actual security needs of the site,combined with the requirements of the hierarchical protection system,security measures such as network security domain division,network logical isolation,network physical isolation,identity authentication enhancement,and security operation and maintenance audit are adopted to build a longitudinal security defense system that integrates protection,detection,response,and recovery.The train dispatching command system/dispatching centralized system is selected as an exemplary research object,and the practical application scheme and security value are practiced and analyzed.The protective measures proposed in the study can effectively resist the existing security risks in the railway signaling system,improve the network security guarantee capability,and ensure the safe and stable operation of the railway signaling system.
作者
张晶
余卫巍
Zhang Jing;Yu Weiwei
出处
《铁道通信信号》
2022年第11期48-52,共5页
Railway Signalling & Communication
关键词
铁路信号系统
网络安全
风险
安全管理
等级保护
态势感知
Railway signaling system
Network security
Risk
Security management
Grade protection
Situational awareness